[ovirt-users] Re: CVE-2024-1597

2024-02-21 Thread Jean-Louis Dupond via Users
The fix got merged into the 42.2.x branch: https://github.com/pgjdbc/pgjdbc/commits/release/42.2/ So guess we just need to bump the dep in the pom. But as far as I see the code doesn't use the PreferQueryMode flag, so we're save. Jean-Louis On 21/02/2024 09:30, Fabrice Bacchella via Users

[ovirt-users] Re: CVE-2024-1597

2024-02-21 Thread Fabrice Bacchella via Users
I think there is a typo in the announcement. 42.2.8 is 4 year old, 42.2.28 was issued this night. That’s suspicious. > Le 21 févr. 2024 à 09:24, Sandro Bonazzola a écrit : > > I'm not an expert on this topic, but according engine's pom we are using > 42.2.27 which doesn't seem to be in the

[ovirt-users] Re: CVE-2024-1597

2024-02-21 Thread Sandro Bonazzola
I'm not an expert on this topic, but according engine's pom we are using 42.2.27 which doesn't seem to be in the list of the affected version on https://github.com/advisories/GHSA-xfg6-62px-cxc2 Il giorno mer 21 feb 2024 alle ore 09:09 Fabrice Bacchella via Users < users@ovirt.org> ha scritto: >